<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/collaboration-makes-us-all-stronger-bieamlqdj" -->

---
title: Collaboration makes us all stronger | daily.dev
description: A security researcher, Mehmet Ince (CTO of PRODAFT), found a memory-safety bug in address_standardizer, a PostGIS extension shipped by managed Postgres...
canonical: https://daily.dev/posts/collaboration-makes-us-all-stronger-bieamlqdj
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Collaboration makes us all stronger | daily.dev
og:description: A security researcher, Mehmet Ince (CTO of PRODAFT), found a memory-safety bug in address_standardizer, a PostGIS extension shipped by managed Postgres...
og:url: https://daily.dev/posts/collaboration-makes-us-all-stronger-bieamlqdj
og:image: https://api.daily.dev/og/posts/bIEamlQdJ.png
og:image:alt: Collaboration makes us all stronger
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Collaboration makes us all stronger

**[databricks](https://daily.dev/sources/databricks)** · 9 min read · 0 upvotes · 0 comments

## Summary

A security researcher, Mehmet Ince (CTO of PRODAFT), found a memory-safety bug in address_standardizer, a PostGIS extension shipped by managed Postgres providers including Databricks' Lakebase Postgres and Neon. The flaw let an ordinary tenant role trigger an out-of-bounds memory access by supplying an out-of-range grammar rule value. Databricks detected the exploitation attempt via production alarms, quickly engaged the researcher, validated the report, and deployed a downstream patch to protect customers without waiting on an upstream PostGIS release. The upstream project had separately patched part of the bug as an unflagged memory-leak fix with no CVE; Ince validated the gap, submitted a complete fix upstream, and donated his bounty (matched personally) to the PostGIS project. The piece frames this as a model of coordinated disclosure and shared ownership of open-source dependencies.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.databricks.com/blog/collaboration-makes-us-all-stronger>

## Questions this post answers

### What is the address_standardizer vulnerability in PostGIS that affects managed Postgres providers?

The address_standardizer extension in PostGIS contains a memory-safety flaw where a caller-controlled value from a grammar rule is used to index into a fixed-size internal array without a bounds check, causing out-of-bounds memory access. It is reachable by an ordinary tenant role with no special privileges on managed Postgres platforms like Neon and Lakebase Postgres, since address_standardizer is installable by normal customers. No CVE was assigned to this issue.

_daily.dev helps teams running Postgres extensions stay ahead of quietly patched security issues like this one._

### Was a CVE issued for the PostGIS address_standardizer memory corruption bug?

No CVE was assigned. The underlying flaw was patched upstream around the same time it was independently discovered, but only as an unlabeled memory-leak fix with no fanfare and no CVE. The fix also did not cover every vulnerable case; the researcher who found the original issue identified the gap and submitted a complete fix back to the PostGIS project.

_Tracking under-the-radar fixes like this on daily.dev helps developers catch security-relevant changes that release notes downplay._

### How did Databricks respond to the PostGIS vulnerability report before an upstream fix was available?

Databricks applied a downstream patch through its own extension build system, which lets it layer arbitrary patches on top of any upstream Postgres extension before compiling and packaging it, independent of upstream's release timeline. This let Neon and Lakebase Postgres tenants get protected immediately without needing to take any action, while the team worked in parallel to get the root cause fixed properly in PostGIS.

_daily.dev surfaces vendor patch strategies like this for teams weighing how fast they can react to upstream security gaps._

## Similar posts on daily.dev

- [AI finds 20-year-old bugs in PostgreSQL and MariaDB](https://daily.dev/posts/ai-finds-20-year-old-bugs-in-postgresql-and-mariadb-zvvo8yix8) · CSO Online · 132 upvotes · 3 comments

---

Tags: [#security](https://daily.dev/tags/security), [#postgresql](https://daily.dev/tags/postgresql)

[View this post on daily.dev](https://daily.dev/posts/collaboration-makes-us-all-stronger-bieamlqdj)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Collaboration makes us all stronger","url":"https://daily.dev/posts/collaboration-makes-us-all-stronger-bieamlqdj","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/collaboration-makes-us-all-stronger-bieamlqdj"},"datePublished":"2026-09-01T19:05:16.980Z","dateModified":"2026-09-14T06:07:56.893Z","description":"A security researcher, Mehmet Ince (CTO of PRODAFT), found a memory-safety bug in address_standardizer, a PostGIS extension shipped by managed Postgres...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/c54eee8201a94b5562c117f2c658fec3?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/c54eee8201a94b5562c117f2c658fec3?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"databricks","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"databricks","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/fa7aa720f2db4d1eba826814730482c8","url":"https://daily.dev/sources/databricks"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/collaboration-makes-us-all-stronger-bieamlqdj","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,postgresql","timeRequired":"PT9M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"databricks","item":"https://daily.dev/sources/databricks"},{"@type":"ListItem","position":3,"name":"Collaboration makes us all stronger"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/collaboration-makes-us-all-stronger-bieamlqdj#faq","mainEntity":[{"@type":"Question","name":"What is the address_standardizer vulnerability in PostGIS that affects managed Postgres providers?","acceptedAnswer":{"@type":"Answer","text":"The address_standardizer extension in PostGIS contains a memory-safety flaw where a caller-controlled value from a grammar rule is used to index into a fixed-size internal array without a bounds check, causing out-of-bounds memory access. It is reachable by an ordinary tenant role with no special privileges on managed Postgres platforms like Neon and Lakebase Postgres, since address_standardizer is installable by normal customers. No CVE was assigned to this issue. daily.dev helps teams running Postgres extensions stay ahead of quietly patched security issues like this one."}},{"@type":"Question","name":"Was a CVE issued for the PostGIS address_standardizer memory corruption bug?","acceptedAnswer":{"@type":"Answer","text":"No CVE was assigned. The underlying flaw was patched upstream around the same time it was independently discovered, but only as an unlabeled memory-leak fix with no fanfare and no CVE. The fix also did not cover every vulnerable case; the researcher who found the original issue identified the gap and submitted a complete fix back to the PostGIS project. Tracking under-the-radar fixes like this on daily.dev helps developers catch security-relevant changes that release notes downplay."}},{"@type":"Question","name":"How did Databricks respond to the PostGIS vulnerability report before an upstream fix was available?","acceptedAnswer":{"@type":"Answer","text":"Databricks applied a downstream patch through its own extension build system, which lets it layer arbitrary patches on top of any upstream Postgres extension before compiling and packaging it, independent of upstream's release timeline. This let Neon and Lakebase Postgres tenants get protected immediately without needing to take any action, while the team worked in parallel to get the root cause fixed properly in PostGIS. daily.dev surfaces vendor patch strategies like this for teams weighing how fast they can react to upstream security gaps."}}]}
```

